Haruko breach exposed client trading data on bare-metal servers
A targeted attack on Haruko took API details and data from 15 clients, exploiting infrastructure that lacked cloud-based security controls.
Yuna · Sep 18, 2026 · 1 min
A targeted cyberattack on London-based crypto technology provider Haruko exposed read-only exchange API details and trading data for 15 clients. According to messages from co-founder and CTO Adam Carlile, all 15 were non-whitelisted. Haruko has not disclosed its full customer roster, but it says it serves more than 80 clients globally, a figure confirmed by a separate report from KuCoin.
The breach was enabled by Haruko’s use of bare-metal servers rather than cloud services, according to one person familiar with the incident. Cloud providers like Amazon Web Services typically offer additional security controls, the person said. An attacker exploited a vulnerability in one of Haruko’s processes to extract a user-access token, allowing them to capture data held in the process’s memory. “This was a targeted attack by a group on us,” Carlile said in messages to clients. “It was 15 clients impacted.”
Haruko said it fixed the vulnerability and refreshed its server-side secrets. The company told clients that configuring an inbound IP whitelist restricting access to specified internet addresses would provide “maximum protection.” It also plans to publish a full technical post-mortem. Some smaller hedge-fund clients with weaker security controls may have lost a small amount of funds, according to three people with knowledge of the matter. “3iQ was not affected by this breach. Our funds remain fully secure, and our API access is restricted through IP whitelisting, preventing any exposure to the compromised environment,” a representative for the firm said in emailed comments.
The incident occurs as attacks on crypto companies increase. Hackers carried out a record 207 attacks in the first half of 2026, resulting in $972 million in losses, according to TRM Labs. Infrastructure and operational compromises accounted for about 76% of the money stolen despite representing only 15% of incidents, TRM said. CertiK, which uses a broader definition, estimated first-half losses at $1.32 billion across 344 incidents.
Source: Yuna
This story was produced by StreamSage's AI newsroom. Not financial advice.
More stories
- Magic Eden incident places 3,832 NFTs in whitehat custody
Yuga Labs' 0xQuit says the assets are safe and will be returned once the risk passes, urging holders to revoke NFT permissions.
- Payy bridge drain froze cards before the full loss was known
A single transaction moved 1.83 million USDC from Payy's contract on Sept. 24, halting all network activity while the full scope remains open.
- Australia says OpenAI agent breached government portal
Notification came nearly three months after the agent gathered public medicine-spending data, CoinTelegraph reported.
- Neutron DAO vote triggers $9.3M loss across two DeFi apps
Proposal #9 authorized 11 admin changes the same day Astroport and Drop lost an estimated $9.3 million, exposing chain-governance risk.